bono.chat is built to know as little about you as possible. We don’t ask for an account, we don’t profile you, and your messages are end-to-end encrypted and never stored. This policy explains what that means — honestly, including the limits.
The controller of any limited processing described here is Novaserv OÜ (Estonia, registry code 16738144), operator of bono.chat. Contact: privacy@bono.chat.
Conversations are protected with end-to-end encryption. The encryption keys are created on the two participants’ devices. Our relay only passes along encrypted data so the two of you can connect; it is designed as a “zero-knowledge” relay that does not read, log, or store the content of your messages, and we cannot recover them. When a conversation ends, it is gone — there is no history and no message database.
Like any internet service, connecting to our relay necessarily involves some transient technical data — such as your IP address and the timing of the connection — which is processed only to route and maintain your connection. We do not use this to identify you, build a profile, or track you, and we do not retain it beyond what is necessary to operate and protect the Service.
To keep the Service healthy we keep anonymous aggregate operational counters — numbers only, such as how many rooms were created or how much encrypted data passed through on a given day. These are plain totals with no identifiers: no room codes, no IP addresses, no user agents, and nothing tied to an individual conversation or person.
Honest limit: encryption protects the content of your conversation, but it does not hide the fact that a connection happened, and such metadata may be visible to networks or intermediaries between you and the Service. If concealing that a conversation occurred is critical to you, bono.chat alone is not sufficient.
We do not use tracking or advertising cookies, and we do not run third-party analytics. Only strictly necessary, technical storage may be used to make the app function; none of it is used to track you.
To the limited extent any personal data (such as a transient IP address) is processed, we rely on our legitimate interests (Art. 6(1)(f) GDPR) in providing, operating, and securing a functioning service, and on the necessity of processing to deliver the service you request. We minimise such processing by design.
We do not retain message content or conversation history. Transient technical data is not stored as a profile and is kept only as long as strictly necessary to operate and protect the Service, after which it is discarded.
Under the GDPR you have rights to access, rectify, erase, restrict, and object to processing of your personal data, and to lodge a complaint with a supervisory authority (in Estonia, the Data Protection Inspectorate / Andmekaitse Inspektsioon). Because we deliberately hold little or no personal data and cannot link data to an identity, in many cases there will be nothing for us to retrieve or delete. To make a request, contact privacy@bono.chat.
The Service runs on third-party hosting and network infrastructure located in the European Union (Estonia), which processes connection traffic on our behalf as a processor. They do not receive access to message content, which remains end-to-end encrypted.
Our servers are located in the European Union (Estonia). Any necessary processing takes place within the EU/EEA.
The Service is not directed to children under the age of 16, and we do not knowingly process the personal data of children.
We may update this policy from time to time. The “Last updated” date reflects the current version.
Privacy questions or requests: privacy@bono.chat.